Courseiva

VA-003 · domain

troubleshooting

Practise HashiCorp Vault Associate VA-003 troubleshooting practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

366 questions109 easy155 medium102 hard

Focused practice

Practice troubleshooting questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about troubleshooting

troubleshooting questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common troubleshooting exam traps

  • ▸Answering from memory before reading the full scenario.
  • ▸Missing a constraint such as cost, availability, security, scope or command context.
  • ▸Choosing a broad answer when the question asks for the most specific fix.
  • ▸Ignoring why the wrong options are tempting.

Question index

All troubleshooting questions (366)

Click any question to see the full explanation, or start a practice session above.

1

A Vault operator deploys a single Vault server using Integrated Storage (Raft) as the storage backend. After initializing Vault, the operator notices that the server is marked as sealed and cannot serve requests. The operator has the unseal keys but wants to understand the architectural reason why Vault starts sealed after initialization. Which statement best explains why Vault is sealed immediately after initialization?

Medium
2

An application needs to read a secret using the Vault API after authenticating with an AppRole RoleID and SecretID. The application has already obtained a Vault token. Which API endpoint should be called to read a secret at 'secret/data/myapp' with the token?

Easy
3

A security engineer is onboarding a new application team to Vault. The team needs to understand how Vault manages the lifecycle of secrets issued by the database secrets engine. The engineer explains that Vault attaches a lease to dynamic secrets and that the lease defines the secret's validity period. Which statement accurately describes the relationship between a lease and a dynamic secret?

Easy
4

A Vault operator is examining the architecture of a Vault cluster and wants to understand how client requests are routed to the active node. Which component is responsible for forwarding requests from standby nodes to the active node?

Medium
5

A platform team manages a fleet of on-premises Linux servers that are not joined to any cloud provider or Active Directory domain. They want each server to authenticate to Vault automatically at boot without embedding a long-lived token in a configuration file. The team already maintains an internal PKI that issues X.509 certificates to every server. Which authentication method should they enable to meet these requirements with the least new infrastructure?

Medium
6

A small startup wants to run Vault in a development environment with minimal operational overhead. They need to store secrets in memory only, without any persistence. Which storage backend should they choose?

Easy
7

A development team wants to encrypt sensitive data before storing it in a database. They don't want to manage encryption keys themselves. Which secrets engine should they use?

Medium
8

A role in Vault's database secrets engine is configured with default_ttl=30m and max_ttl=2h. An application requests credentials and then successfully renews the lease twice, each time receiving the full default TTL. What is the longest total time the credential can remain valid from its original issue time?

Hard
9

A Vault operator accidentally revoked a token that was used to lease many database credentials. What happens to the leases associated with that token?

Medium
10

A platform team wants Kubernetes pods to authenticate to Vault by presenting their service account token, with Vault verifying the token's validity against the Kubernetes API and checking the pod's namespace and service account name. Which auth method should the team enable?

Hard
11

An e-commerce application integrates with Vault's transit secrets engine to encrypt sensitive customer data before storing it in a database. The operations team regularly rotates the encryption key (my-key) for compliance. Recently, after a rotation, some old ciphertexts could not be decrypted, causing data retrieval failures. The team checked the key configuration and found that the key version used for encryption (version 2) is still present, but decryption fails with an error: 'decryption key version is not available for decryption'. They verified that the ciphertext includes the key version. What is the most likely cause and resolution?

Hard
12

A Vault operator wants to manage lease durations for secrets issued by a PKI secrets engine. Which two actions can they take to affect the lease duration of certificates?

Medium
13

A Vault administrator is designing a disaster-recovery runbook for dynamic secrets and needs to document the ways leases can be terminated or cleaned up. Which two statements correctly describe lease revocation behavior in Vault? (Choose two.)

Hard
14

A Vault operator runs 'vault token lookup s.abc123' and sees that the token type is 'service', renewable is true, but the ttl is 30m and creation_ttl is 1h. The token has num_uses set to 0. What is the most likely explanation for the discrepancy between ttl and creation_ttl?

Hard
15

A Vault administrator needs to create a policy that grants users read access only to the secrets that belong to their own team. The team membership is stored in an external identity provider and mapped to Vault entity aliases. The administrator wants to use a templated policy that references the entity's metadata. Which policy syntax accomplishes this goal?

Hard
16

An administrator receives an access denied error when trying to use the token accessor to revoke a token. The administrator's token has the following policy capabilities: path "auth/token/revoke-accessor" { capabilities = ["create", "update"] }. What is the issue?

Hard
17

A security team wants to allow applications to authenticate to Vault without storing any secrets in configuration files. The applications run on AWS EC2 instances with an IAM role attached. Which Vault authentication method leverages the EC2 instance metadata to obtain credentials?

Easy
18

Which TWO authentication methods are designed for human users? (Choose two.)

Easy
19

A team is migrating from a monolithic application to microservices. Each microservice needs to authenticate to Vault using its own AppRole. The security team wants to enforce that each AppRole can only read secrets from its own dedicated path (e.g., service-a can only read from 'services/service-a/*', service-b from 'services/service-b/*'). They have created the AppRoles and policies. However, during testing, they notice that service-a can read secrets from service-b's path. The administrator checks the policy for service-a and sees it has a 'capabilities' list on 'services/service-a/*' and also 'services/service-b/*' by mistake. They correct the policy, but the issue persists. What is the most likely reason that service-a still has access?

Medium
20

A DevOps team wants to automate authentication to Vault for Jenkins jobs running on AWS EC2 instances. Which authentication method is most appropriate and secure for this use case without storing long-lived credentials?

Easy
21

A token with a policy that explicitly denies 'read' on 'secret/engineering/private' is issued. The same token also has another policy that grants 'read' on 'secret/engineering/*'. What is the result when the token tries to read 'secret/engineering/private'?

Hard
22

Refer to the exhibit. What operation was performed on the secret "mysecret"?

Easy
23

A Vault administrator is troubleshooting a Vault cluster using integrated storage (Raft). The cluster has three nodes: node1 (active), node2 (standby), and node3 (standby). The administrator runs `vault operator raft list-peers` and sees that node3 is listed as a non-voter. What is the most likely reason for node3 being a non-voter?

Medium
24

A Vault administrator is configuring a new Vault cluster with Integrated Storage (Raft). The administrator wants to ensure that the cluster can tolerate the failure of one node without data loss and that writes remain available. What is the minimum number of nodes required, and what is the recommended configuration for high availability?

Hard
25

A new engineer authenticates to Vault and receives a token. The engineer's manager asks which policies are attached to that token and when it will expire, so the team can plan a permissions review. Which command should the engineer run to display this information about their own token?

Easy
26

A security team needs to grant a service account the ability to read secrets from the path 'secret/data/backup' and also to update the secret at that same path. Which policy correctly implements this requirement?

Easy
27

A platform team stores KV v2 secrets under the mount 'kv-prod'. They need a policy that lets an application read only the metadata (not the underlying secret values) for every path under 'kv-prod/apps/', including the ability to enumerate keys. Which policy stanza satisfies this requirement?

Medium
28

An application stores ciphertext produced by a Vault transit key named `orders` in a database. The security team rotates the key with `vault write -f transit/keys/orders/rotate`. After rotation, the application reports that decryption of previously stored records fails. The key was never deleted or reconfigured. What is the most likely cause?

Medium
29

A user wants to view information about their current token, including its policies and TTL. Which TWO CLI commands can be used?

Medium
30

A security team needs to create a Vault policy that allows a token to read secrets under 'secret/data/finance/*' but explicitly denies access to 'secret/data/finance/salaries'. The policy must also allow listing all secrets under 'secret/data/finance/'. Which policy definition correctly achieves this?

Hard
31

Which THREE steps are required to configure the database secrets engine for a MySQL database?

Medium
32

A platform team runs a Vault cluster where many applications obtain dynamic AWS credentials from the aws secrets engine. During an incident, an operator needs to stop all credential usage tied to a compromised IAM role without disrupting other roles. The operator has a root token and wants to revoke every lease associated with that specific role. Which approach accomplishes this?

Medium
33

A CI/CD pipeline needs to generate thousands of short-lived tokens each day for jobs that run for at most 5 minutes. The tokens should not be renewable or revocable individually. Which token type should be used?

Medium
34

Which THREE of the following are true about the KV v2 secrets engine? (Select exactly 3.)

Hard
35

A large enterprise runs Vault in a high-availability cluster with integrated storage (Raft). They notice that read requests are not being evenly distributed across nodes, causing some nodes to have high load. They want to offload read operations to standby nodes. What feature should they enable to achieve this?

Hard
36

An administrator notices that after revoking a specific lease, the underlying database credential is still accessible. What is the most likely cause?

Hard
37

A security team must immediately invalidate every dynamic database credential issued under a specific role named app-readonly, across all database mounts, without knowing individual lease IDs. Which Vault command accomplishes this?

Medium
38

An administrator configures a database secrets engine with a role that uses 'creation_statements' and 'revocation_statements'. However, when a lease expires, the database user is not revoked. What is the most likely cause?

Hard
39

Which TWO of the following are true about token accessors?

Medium
40

Which three statements about lease renewal are correct? (Choose three.)

Hard
41

An application team is using a batch token to authenticate to Vault for a long-running data processing job. The token was created with a TTL of 8 hours and no explicit max TTL. After 4 hours, the application attempts to renew the token but receives an error. What is the most likely reason for the renewal failure?

Medium
42

An application needs to encrypt sensitive data before storing it in a database. The security team wants to use Vault's encryption as a service to avoid managing encryption keys. Which Vault secrets engine should they enable?

Easy
43

A DevOps team uses Vault to store database credentials via the database secrets engine. They notice that after the default lease duration, applications receive errors when trying to connect. The team wants to ensure that applications automatically renew leases before expiration. What should they do?

Medium
44

An application authenticates to Vault using the AppRole auth method and needs to retrieve the token's remaining TTL and renewable status programmatically. The application already has a valid token and calls the lookup-self endpoint. Which response fields should it read to determine whether the token can be renewed and how long it remains valid?

Medium
45

Refer to the exhibit. A user with this policy attempts to read 'secret/data/team/admin'. What will happen?

Medium
46

A platform team is standardizing on the transit secrets engine for application-level encryption and wants to understand what the engine can and cannot do before rollout. Which TWO statements accurately describe transit engine behavior? (Choose two.)

Medium
47

Which TWO statements are true when troubleshooting a failed Vault CLI command?

Easy
48

A Vault policy must allow a service to read secrets from "secret/data/app" and also be able to renew its own token. Which two policy statements are necessary and sufficient for this requirement? (Select two.)

Hard
49

A Vault cluster uses Integrated Storage. During a planned upgrade, the administrator wants to minimize downtime. Which upgrade strategy should be used?

Hard
50

Which two commands can be used to manually revoke leases? (Choose two.)

Medium
51

What is the purpose of the Seal/Unseal process in Vault architecture?

Easy
52

After a Vault migration, some leases are no longer valid and cause errors. What is the best way to force a cleanup of all leases under a specific mount without affecting other mounts?

Hard
53

An organization has two Vault clusters in different geographic regions and wants to replicate secrets from the primary cluster to the secondary cluster for disaster recovery. Which Vault replication feature should they use?

Easy
54

A DevOps team needs to provide temporary database credentials to applications without storing long-lived passwords. Which secrets engine should they use?

Easy
55

What happens when a lease reaches its TTL?

Easy
56

Match each Vault audit device to its output destination.

Medium
57

A security engineer needs to choose an authentication method for a set of microservices running in a Kubernetes cluster that require short-lived secrets. The method should leverage the pod's identity. Which method is best?

Easy
58

Refer to the exhibit. Which authentication method is currently enabled for production applications?

Easy
59

An organization uses Vault to issue certificates via the PKI secrets engine. They have set the default lease TTL on the PKI mount to 72h, and the role's ttl to 24h. A user requests a certificate with a requested TTL of 48h. What will be the actual TTL of the issued certificate?

Hard
60

A token has the properties shown in the exhibit. A user attempts to use this token to write a secret to 'secret/data/myapp'. The token fails with a permission denied error. What is the most likely cause?

Medium
61

A security team wants to store static secrets like API keys in Vault. They need the secrets to be versioned and support rollback. Which secrets engine should they use?

Easy
62

A Vault operator needs to let an on-premises LDAP directory's groups map directly to Vault policies, but the directory does not implement any OIDC or SAML endpoints. Which auth method should the operator enable to authenticate users against that directory?

Medium
63

An operator inspects a Vault policy and finds a rule granting read on database/creds/reporting. Applications using tokens bound to this policy can fetch credentials but receive permission denied when they attempt to extend them. Which capability must be added to the policy to allow lease renewal?

Medium
64

A Vault cluster with three nodes using Integrated Storage (Raft) is healthy with one active and two standby nodes. A network partition isolates the active node. What will happen?

Medium
65

A company uses Vault for secrets management. They want to authenticate using GitHub tokens, but only for users who are members of a specific GitHub team. What must be configured?

Hard
66

The CLI command returns a 403 error. What is the most likely cause?

Easy
67

A startup uses Vault to manage secrets for their web application. They currently have a single admin user who authenticates with a root token. They want to allow two developers to authenticate with their own credentials and restrict them to read-only access to a specific path 'secret/data/webapp'. They decide to use the Userpass auth method. The admin creates a user 'dev1' with password 'password123' and assigns a policy 'webapp-readonly' that grants read capability on 'secret/data/webapp'. However, when dev1 tries to log in, Vault returns a permission denied error. The admin checks the token and sees no policies attached. What is the most likely issue?

Medium
68

A user's token was revoked by an administrator, but the user can still read secrets from a KV v1 secrets engine. What is the most likely reason?

Medium
69

A company is migrating from a file storage backend to Consul. Which Vault command should be used to move the data?

Easy
70

Which TWO best practices should be followed when tuning secrets engine mounts?

Hard
71

A company runs its containerized workloads on multiple Kubernetes clusters and also maintains a number of legacy virtual machines running critical applications. The Vault cluster is deployed outside Kubernetes and is used to manage secrets for both environments. The DevOps team has configured the Kubernetes auth method for pods in the Kubernetes clusters, but they are experiencing authentication failures for pods in one specific namespace. Meanwhile, legacy VMs cannot authenticate at all because they are not part of any Kubernetes cluster. The Vault administrator needs to enable authentication for all workloads while minimizing changes to existing applications. The administrator has received the following requirements: containerized pods should authenticate without manual token distribution, legacy VMs should use a method that supports machine-oriented authentication with short-lived tokens, and all authentication should be auditable. Which course of action should the administrator take?

Medium
72

A company's CI system runs outside any cloud provider and must authenticate to Vault without embedding a long-lived secret in its build scripts. The security team wants the CI job to prove its identity using a credential that Vault validates against the CI platform itself. Which auth method best fits this requirement?

Medium
73

A user wants to log in using the userpass auth method with username 'jdoe' and password 'p@ssw0rd'. What is the correct API endpoint and request?

Easy
74

Refer to the exhibit. A Vault policy allows 'list' on 'secret/data/*'. A user tries to list keys under 'secret/data/' and gets a permission denied error. What is the most likely reason?

Easy
75

A user attempts to read a secret at path 'secret/data/app' and receives a 403 Forbidden error. What is the most likely cause?

Medium
76

Which TWO of the following are benefits of using Vault's transit engine for encryption as a service?

Hard
77

A company with strict security requirements uses Vault's Transit secrets engine to encrypt data in a microservices architecture. They have multiple applications that each require a unique encryption key. The security team wants to enforce key rotation every 30 days for all keys, and also require that keys be destroyed after they are no longer used. The application team is concerned that key rotation might cause downtime because applications need to re-encrypt data. The Vault architect needs to design a key management solution. What is the best approach?

Hard
78

A security architect is designing authentication for an internal tool that must verify a user's hardware-backed token on a smart card before granting access to secrets. The tool already has a PKI issuing client certificates to each user, and the architect wants Vault to validate the client certificate chain during login. Which auth method should be used, and what is the key configuration requirement?

Hard
79

A security team encrypts records with a transit key and stores the resulting ciphertext. Months later they rotate the key several times. An application now needs to read old records, and the team also wants future writes to use only the newest key version without breaking decryption of the legacy rows. What is the accurate behavior of the transit engine in this situation?

Hard
80

A developer wants to encrypt data using Vault's transit engine with a key named 'payment-key'. The key already exists and is set to allow encryption. Which API path should the developer use to encrypt the data?

Easy
81

A security team must delegate policy management to a group of operators without giving them the ability to grant themselves capabilities on protected paths such as 'sys/*' or 'auth/token/*'. Which combination of policy rules best implements this delegation safely?

Hard
82

A platform team runs a nightly batch job that authenticates to Vault with the AppRole auth method and receives a token with a 30-minute TTL. The job occasionally overruns and hits 'permission denied' errors mid-run. The team wants the token to stay valid as long as the job keeps working, without the job re-authenticating. Which token attribute should the AppRole role be configured with when the token is issued?

Medium
83

A security engineer is reviewing Vault's architecture and asks about the component that stores the actual encrypted data. Which Vault component is responsible for persisting encrypted secrets and configuration data?

Easy
84

A developer wants to encrypt a string "hello" using Vault's transit engine. What must they send in the API request?

Easy
85

An operator needs to enable the KV v2 secrets engine at the path 'team-alpha'. Which command should they run?

Easy
86

A Vault cluster uses DR replication. The primary cluster fails, and the DR secondary is promoted to primary. After promotion, some secret data written to the primary shortly before the failure is missing on the new primary. What is the most likely reason?

Hard
87

A consulting firm deploys Vault to multiple tenants. Each tenant uses the OIDC auth method with its own identity provider, but the security team observes that users from one tenant occasionally receive policies intended for another tenant. The OIDC mounts were configured separately, and each uses a distinct default_role. Which configuration issue most likely explains the cross-tenant policy assignment?

Hard
88

A company needs to generate short-lived, dynamic database credentials for its MySQL instances. Which secrets engine should be configured?

Easy
89

A Vault administrator has enabled the PKI secrets engine and configured a root CA. They now need to issue certificates for multiple internal services, each with its own common name (CN). Which is the most efficient way to issue certificates while maintaining security?

Medium
90

Refer to the exhibit. A token has this policy. Which action can the token perform?

Easy
91

An operator needs to perform token lifecycle operations. Which THREE API endpoints are valid for token-related actions?

Hard
92

An application stores user profile documents in a database and must encrypt field values with Vault's transit engine. A reviewer notes that anyone with the application's token could still send arbitrary ciphertext to the decrypt endpoint and read the result. The team wants to limit blast radius if the token leaks. Which transit engine capability best reduces this risk?

Medium
93

During a security assessment, a penetration tester discovers that Vault's seal configuration uses a single master key stored in a file on the server. The attacker gains root access to the server and retrieves the unseal key. What is the best mitigation to prevent this scenario?

Hard
94

After migrating from an older version of Vault, the operator wants to replace the deprecated 'generic' secrets engine with a modern alternative. Which secrets engine should be used to store static key-value pairs?

Easy
95

A company uses Vault Enterprise with Performance Replication. The primary cluster is in us-east-1, and a secondary cluster is in eu-west-1. Clients in eu-west-1 report that they receive stale data when reading from the local secondary cluster's active node. What is the most likely cause?

Hard
96

A DevOps engineer configures the AWS secrets engine to assume a specific IAM role for generating dynamic credentials. The engine is enabled and the root configuration is set. Which parameter is essential in the role configuration to allow assuming the IAM role?

Hard
97

A DevOps team needs to encrypt sensitive configuration data before storing it in a version control system. They want to use Vault's encryption as a service to encrypt the data using a named encryption key. Which Vault path should they use to perform the encryption?

Easy
98

Refer to the exhibit. A user deletes the current version of 'secret/myapp' using 'vault kv delete secret/myapp'. What happens to the version?

Medium
99

An organization previously used userpass auth and is migrating to LDAP auth. After enabling LDAP and configuring the bind user, users can authenticate but their policies do not apply. What is the most likely cause?

Medium
100

Which TWO of the following are components of Vault's architecture? (Choose two.)

Medium
101

Which Vault CLI command is used to authenticate a user with a username and password to the userpass auth method?

Easy
102

A company is deploying Vault in a high-availability configuration across three data centers. They need to ensure that if the active Vault node fails, another node can take over without manual intervention. Which Vault feature should they configure?

Medium
103

A platform team uses Vault to issue short-lived tokens to external contractors. The security policy requires that every contractor token must be traceable back to the contractor's identity, and that a token can never be renewed beyond its initial TTL. The team creates tokens with the default settings. A contractor later reports that their token stopped working after its TTL expired, but they were able to renew it several times before that. Which token parameter should the team have configured to enforce the policy?

Medium
104

An administrator enables the database secrets engine for PostgreSQL. After configuring the connection, running `vault write database/config/someconfig` yields error: 'x509: certificate signed by unknown authority'. What is the most likely cause?

Hard
105

A database secrets engine is configured at database/ with a connection to PostgreSQL and a role named app-readonly. The role uses creation_statements to create a user with a random password and a TTL of one hour. An application retrieves credentials and uses them successfully, but after the lease expires the database user still exists and can log in. Which configuration change should the administrator make to ensure the user is removed when the lease ends?

Hard
106

A Vault administrator needs to delegate the ability to create tokens to a user without granting full administrative privileges. Which token type should the administrator create for the user to allow them to create tokens with specific policies?

Easy
107

Which TWO of the following Vault CLI commands can be used to write data to Vault?

Medium
108

An administrator wants to retrieve the value of a secret stored at the path 'kv/secret/mykey' using the Vault CLI. Which command should they use?

Easy
109

Which token type should be used for short-lived credentials that do not need to be renewed?

Medium
110

A platform engineer has issued dynamic AWS credentials through Vault's AWS secrets engine and wants to extend the usable lifetime of that credential before it expires. Which Vault CLI command allows the engineer to request additional time on the lease?

Easy
111

A security engineer is troubleshooting why a Vault token cannot be renewed. The token was created with a TTL of 4 hours and is renewable. After 2 hours, the engineer attempts to renew it using `vault token renew <token>` but receives the error: "lease not found". The engineer confirms the token is still valid and not expired. Which of the following is the most likely cause?

Hard
112

What is the purpose of a token's "period" attribute?

Easy
113

A development team is building a microservices application that needs to encrypt sensitive customer data before storing it in a shared database. They want to minimize changes to their existing code and avoid managing encryption keys themselves. Which Vault feature should they use?

Medium
114

Where can you view a list of all active tokens in Vault?

Easy
115

A company stores static secrets in Vault and requires that all data is encrypted at rest in the storage backend. Which Vault feature provides this encryption?

Easy
116

An application is failing to decrypt data using the transit secrets engine. The ciphertext was generated with key 'my-key' version 3, but the engine currently shows key version 5. What is the most likely cause of the failure?

Hard
117

An administrator wants to use Vault's authentication method that allows users to log in with their corporate credentials via a federated identity system. The credentials are stored in an external identity provider (IdP) and Vault should not store any passwords. Which authentication method should be configured?

Medium
118

An organization uses the AWS secrets engine to generate IAM users dynamically. They notice that the generated IAM user is not immediately available for use in AWS. What is the most likely reason?

Hard
119

A Vault operator needs to enable the `userpass` auth method at the path `auth/legacy-userpass` and then create a user named `svc-backup` with a password, all from a CI script. Which single command correctly enables the auth method at that custom path?

Medium
120

A DevOps engineer needs to create a token that can only read secrets under the path 'secret/engineering'. What is the recommended approach?

Easy
121

A developer wants to authenticate to Vault using a username and password without any external identity provider. Which authentication method should be enabled?

Easy
122

A company needs to automatically generate short-lived database credentials for developers. Which secrets engine should they use?

Easy
123

A company has a Vault cluster and wants to allow applications running in Kubernetes pods to authenticate without storing static secrets. Which Vault authentication method is specifically designed for Kubernetes?

Medium
124

A token is created with policies 'default' and 'web-app'. Later, a parent token's policy is updated to add 'logging'. The child token's policies are not updated. What will happen when the child token is used?

Hard
125

An organization is implementing Vault policies for the first time. They want to ensure that policies are easy to manage and follow the principle of least privilege. Which approach should they take when creating policies?

Easy
126

A Vault administrator needs to allow users to authenticate using their existing corporate Active Directory credentials. The administrator has configured the LDAP authentication method but users cannot log in. The Vault logs show 'LDAP bind successful' but then 'user not found in group' error. What is the most likely issue?

Medium
127

A company has deployed Vault with an LDAP auth method and has created entity aliases for all users. The company uses KV v2 secrets engine mounted at 'secret/'. Each team's secrets are stored under a path like 'secret/data/team_<team_name>/'. They have multiple teams (engineering, marketing, sales). Currently, an administrator manually creates a separate policy for each team, e.g., path "secret/data/team_engineering/*" { capabilities = ["read", "list"] }. This is becoming cumbersome as new teams are added. The administrator wants to create a single policy that dynamically grants read access to the secrets path corresponding to the user's team, which is stored in the entity's metadata as 'team'. The LDAP auth method is configured to sync group memberships and map to entity aliases, and the entity metadata is correctly populated. Which approach should the administrator take?

Medium
128

A platform team is designing an encryption-as-a-service layer with the transit secrets engine for several internal applications. They want to minimize the amount of sensitive data that reaches application memory and reduce the operational cost of rotating keys. Which TWO design choices align with how the transit engine is intended to be used? (Choose two.)

Hard
129

A company uses both userpass and AppRole authentication methods. They notice that tokens issued via AppRole are not properly revoked when the corresponding secret_id is deleted. Which concept explains this behavior?

Hard
130

A Vault cluster configured with auto-unseal using AWS KMS is deployed across two availability zones. After a network partition, the standby node remains sealed while the active node is unsealed and serving requests. What is the most likely reason the standby cannot unseal?

Hard
131

A DevOps team is using Vault's database secrets engine to generate dynamic credentials for a PostgreSQL database. They notice that the lease duration is set to 24 hours, but security policy requires that credentials expire after 1 hour. What should the team do to enforce the 1-hour expiration without changing the default lease TTL for all secrets?

Medium
132

An admin creates a token with TTL=48h and explicit_max_ttl=120h. The token is renewed every 24h. After 10 days, will the token still be valid?

Hard
133

Refer to the exhibit. Based on the output from 'vault status', which statement is true?

Hard
134

A developer wants to inspect the metadata of the current Vault token, including its attached policies, TTL, and whether it is renewable, using a single CLI command. Which command should the developer run?

Easy
135

A Vault administrator is writing a policy for a monitoring tool that must be able to list all secrets under the 'secret/metadata/finance/' path and read the metadata of individual secrets, but must not read the secret data itself. Which policy snippet correctly grants only these permissions?

Medium
136

An application uses a Vault token with a policy that grants read access to secrets. The security team wants to ensure that if the application is compromised, the token cannot be used after a certain time even if the attacker has the token. What is the best approach?

Hard
137

A compliance team is evaluating the Vault transit secrets engine as encryption as a service for several internal applications. They want to confirm which statements accurately describe how the engine behaves. (Choose two.)

Medium
138

A security architect is designing a secrets management solution with Vault. Which THREE secrets engines are most appropriate for dynamically generating credentials for external systems?

Hard
139

Drag and drop the steps to create and use a periodic service token in Vault into the correct order.

Medium
140

An organization wants to use Vault to generate AWS IAM users with specific managed policies attached. They have configured the AWS secrets engine with the appropriate IAM credentials. What step is required to ensure each generated user gets the correct policies?

Medium
141

Refer to the exhibit. A Vault administrator starts a Vault server and receives this error. What is the most likely cause?

Easy
142

A platform team runs Vault in an on-premises data center. Their legacy monitoring appliance cannot present a TLS client certificate and has no cloud identity provider, but it does have a dedicated filesystem path where it can read a small configuration file written at deployment time. The team wants the appliance to authenticate on a schedule with credentials that can be issued per appliance, scoped by policy, and revoked without affecting other appliances. Which authentication method best fits this requirement?

Medium
143

A cloud engineer is scripting against the Vault HTTP API and must authenticate, then read a KV v2 secret, using only `curl`. Which TWO request elements are required for the read to succeed? (Choose two.)

Hard
144

An administrator needs to revoke a token but wants to keep all child tokens that were created using this token as the parent. Which revocation operation should be used?

Easy
145

Refer to the exhibit. A user with this policy attempts to read the secret at path "secret/data/team-a/admin". What will happen?

Medium
146

A DevOps team wants to authenticate a CI/CD pipeline running on a Jenkins server outside Kubernetes. The pipeline needs to obtain short-lived tokens to read secrets. Which authentication method should be used?

Easy
147

An admin is troubleshooting a Vault cluster where some dynamic secrets leases are not being revoked after their TTL expires. The admin confirms that the TTLs are set correctly. Which Vault component is responsible for revoking expired leases?

Medium
148

Which Vault component is responsible for encrypting data before storing it in the storage backend?

Easy
149

Which TWO are benefits of using Vault's encryption as a service?

Easy
150

A Vault admin needs to revoke all leases under the `database/creds/readonly` path without revoking leases from other paths. Which command should the admin use?

Easy
151

A DevOps team is using Vault tokens for authentication in CI/CD pipelines. They notice that tokens are often expired before the pipeline completes, causing failures. Which Vault feature should they use to address this without manual intervention?

Medium
152

A security team is configuring the AWS secrets engine to issue dynamic IAM credentials. They want to allow Vault to assume an IAM role and generate temporary credentials for consumers. Which TWO configuration elements are required to enable this workflow? (Choose two.)

Medium
153

A Vault administrator is creating a policy for an application that needs to read a PKI role configuration and also generate certificates using that role. The PKI secrets engine is mounted at 'pki/'. Which policy snippet grants the minimum required capabilities?

Hard
154

A company runs multiple microservices in a Kubernetes cluster. Each microservice authenticates to Vault using a service token created via the token auth method. The tokens are created with a default TTL of 72h, a max TTL of 168h, and renewable set to true. The services are configured to renew their tokens when the remaining TTL drops below 24h. Recently, some tokens have been expiring prematurely, causing service outages. Upon investigation, you find that the expired tokens were created with a role that includes explicit_max_ttl = 72h. The services see the TTL decreasing normally, but then it jumps to zero even though the services attempted renewal. What is the most likely cause and correct action?

Easy
155

A Vault administrator is investigating a production incident where an application's dynamic database credentials stopped working earlier than expected, even though the lease had not reached its maximum TTL. The administrator reviews the role configuration and finds default_ttl=1h and max_ttl=24h. The application typically renews its lease every 30 minutes. Which factor most likely explains why the credentials became invalid before max_ttl was reached?

Hard
156

A Vault administrator is building a policy for an application team that needs to manage PKI certificates issued by the 'pki_int' intermediate mount. The team must be able to generate new certificates from the 'web-server' role and revoke certificates, but must not be able to modify the role, generate a root CA, or configure the mount. (Choose two.)

Medium
157

Refer to the exhibit. A DevOps engineer runs `vault read -format=json transit/keys/mykey` and receives the output shown. A microservice attempts to decrypt data that was encrypted with version 1 of the key. Will the decryption succeed?

Medium
158

A developer wants to authenticate to Vault using LDAP credentials. Which CLI command should they use?

Easy
159

An organization uses Vault with LDAP authentication. Users report they are unable to log in, and the administrator sees errors like 'LDAP bind failed: invalid credentials' in the Vault logs. The LDAP server is reachable. What is the most likely cause?

Hard
160

Drag and drop the steps to set up Vault's Transit secrets engine for encryption/decryption into the correct order.

Medium
161

A Vault operator runs `vault status` and sees the output above. The Vault cluster is in production and currently unresponsive to API requests. What is the most likely cause of the unresponsiveness?

Easy
162

A developer is writing a microservice that must encrypt a small JSON payload using the transit secrets engine's 'orders' key, but the service must never be able to read the key material itself. Which API call should the service use to obtain ciphertext?

Easy
163

A platform team operates Vault in a hybrid cloud. They want a single authentication method that lets employees use their existing cloud provider identity (e.g., AWS IAM role, Azure managed identity) to log in without distributing Vault-specific credentials. Which authentication method should they enable?

Medium
164

A DevOps team needs to encrypt large files (several GB) using Vault's transit engine. What is the recommended approach?

Easy
165

Refer to the exhibit. A developer reports that a token they created using `vault token create -policy=my-policy -ttl=2h` is no longer working after 1 hour. The token lookup output shows the token details. What is the most likely cause?

Hard
166

What is the primary purpose of the Vault transit secrets engine?

Easy
167

An application team needs to encrypt short-lived session tokens before writing them to a Redis cache. They want to avoid handling or storing encryption keys in the application and need the ability to decrypt tokens later without re-encrypting. Which Vault transit secrets engine operation should they use to protect the data at write time?

Easy
168

A new Vault administrator unseals Vault using a single unseal key, but the Vault remains sealed. What is the most likely cause?

Easy
169

An administrator has created a policy file named 'app-policy.hcl'. Which command should they use to upload this policy to Vault?

Easy
170

Which TWO of the following are valid uses of a token accessor? (Select exactly 2 options.)

Easy
171

A platform team runs Vault in a hybrid cloud and wants to let engineers log in with their existing corporate identities held in Okta, without creating separate Vault usernames or passwords. The Okta tenant supports OpenID Connect and exposes a discovery document. Which authentication method should they enable to meet this requirement with the least administrative overhead?

Medium
172

A junior administrator writes a policy file and applies it with 'vault policy write app-read app-read.hcl'. Later, a token created against this policy can read secrets it was never meant to see. The administrator wants to confirm exactly what the policy grants before rotating credentials. Which command displays the parsed, effective rules of the stored policy?

Easy
173

Which TWO statements about Vault's Storage Backend are correct?

Easy
174

Drag and drop the steps to configure Vault's PKI secrets engine to issue certificates into the correct order.

Medium
175

An application encrypts records with the transit engine and stores the ciphertext. A compliance requirement mandates rotating the encryption key every 90 days, but the existing records must remain readable and the application cannot be changed to re-encrypt them all at once. What should the operator do?

Hard
176

An operator wants to enable the database secrets engine at a custom path 'db-creds'. Which command should be used?

Medium
177

Refer to the exhibit. A user has a token with a policy that grants 'read' on 'secret/*'. The user attempts to read the secret at 'secret/data/app' using `vault kv get secret/data/app` but receives a '404 Not Found' error. The user can successfully list the engine at 'secret/' with `vault secrets list`. What is the most likely cause of the 404 error?

Medium
178

An administrator wants to audit token usage without exposing the actual token IDs to auditors. Which approach should they use?

Hard
179

A token with the above policy attempts to look up its own token by calling the accessor endpoint. What will happen?

Easy
180

A Vault administrator is configuring a new Vault server and wants to ensure that audit logs capture every request and response, including the ability to detect tampering. Which Vault architectural component is responsible for providing this capability?

Easy
181

Which TWO of the following are benefits of using dynamic secrets engines (e.g., database, AWS) over static secrets?

Medium
182

An operator has authenticated to Vault and wants to inspect the metadata of the currently active token, including its accessor, policies, and creation time, without exposing the token's secret value. Which CLI command returns this information?

Medium
183

An administrator configures AppRole with a RoleID and SecretID. They want to ensure that each SecretID can be used only once. Which configuration should they use?

Hard
184

An organization uses the KV v2 secrets engine mounted at 'kv/'. They need to permanently delete all versions of a secret at path 'kv/apps/prod/db' and also remove all associated metadata, including custom metadata and version history. Which command should they run?

Hard
185

An operator creates a batch token for a one-time database migration. The migration finishes, and the operator wants the token to be unusable immediately, even before its TTL expires, and wants to confirm the token no longer appears in the token list. Which Vault command accomplishes this?

Hard
186

Refer to the exhibit. A user attempts to renew the token after 20 hours. What will happen?

Hard
187

An operator runs `vault token create -policy=app -ttl=1h -explicit-max-ttl=2h` and then checks the token's properties with `vault token lookup`. The token is renewable. A developer asks whether the token can be kept alive indefinitely by renewing it every 30 minutes. What should the operator tell the developer?

Medium
188

An administrator is configuring Vault to allow employees to log in using their existing corporate credentials managed by an external identity provider that supports OIDC. The administrator wants to avoid creating local Vault users. Which authentication method should be used?

Medium
189

A developer needs to manually revoke a token but only knows its accessor. Which Vault API endpoint can be used to revoke the token using only the accessor?

Medium
190

A Vault administrator is troubleshooting a batch of revoked database credentials. An application reported that its lease stopped working even though the application had been renewing it every few minutes. Reviewing the mount configuration, the administrator sees default_lease_ttl set to 15m and max_lease_ttl set to 2h. The application log shows successful renewals until roughly the two-hour mark, after which the renew call returned an error and the credential failed. What is the most likely explanation?

Hard
191

A cloud operations team wants to use Vault to generate dynamic credentials for an AWS RDS MySQL database. They have configured the database secrets engine and created a role named 'app-role' that maps to a database creation statement. A developer needs to obtain a username and password to connect to the database. Which command should the developer run to retrieve the dynamic credentials?

Easy
192

A Vault user wants to check the capabilities of their token on a specific path. Which command should they use?

Easy
193

A financial services company runs a microservices application on Kubernetes. Each service needs to authenticate to Vault using Kubernetes auth and then read secrets from a shared KV v2 engine mounted at 'shared-kv'. The security team requires that Service-A can only read secrets under 'shared-kv/team-alpha/*' and Service-B can only read secrets under 'shared-kv/team-beta/*'. The Vault administrator has already configured the Kubernetes auth method and created roles for each service with bound service account names. However, both services are currently able to read all paths under 'shared-kv/'. The administrator wants to enforce the least privilege access. Which course of action should the administrator take?

Medium
194

A financial services company uses HashiCorp Vault's transit engine to encrypt customer credit card numbers. The application sends each credit card number individually to Vault for encryption, and the response time is acceptable. However, during peak hours, the company needs to encrypt large batches of 10,000 credit card numbers. Users report that encrypting the entire batch takes several minutes, causing timeouts. The Vault cluster is healthy and not under high load. The security team wants to reduce the encryption time without changing the encryption algorithm or key strength. What should they do?

Medium
195

A developer authenticates with the userpass auth method and receives a token. The developer needs to perform a sensitive operation but the token lacks the required policy. Before asking an administrator, the developer wants to determine whether their current token is permitted to update the secret at secret/data/payments. Which command should the developer run?

Medium
196

A user with this policy wants to delete secrets under the 'team/' path. Which additional capability must be added?

Hard
197

A small company uses Vault with LDAP authentication for their employees. They configured the LDAP auth method pointing to their on-premises Active Directory. Several users report that they can log in to the Vault UI, but they cannot see any secrets in the paths they expect. The administrator verified that the users are in the correct AD groups. The Vault policies are defined and assigned to groups via the LDAP auth method's group mapping. However, the users still have no permissions. What is the most likely root cause and the correct fix?

Easy
198

A security team wants to ensure that tokens can be revoked immediately if a compromised token is detected, even if the token ID is unknown. Which token feature should they use?

Easy
199

A company has multiple AWS accounts and wants to allow EC2 instances to authenticate to Vault without storing any secrets on the instances. Which authentication method should they use?

Medium
200

An administrator creates a service token with a TTL of 1 hour and a max TTL of 24 hours. The token is renewed once after 55 minutes. What happens to the token after 24 hours from creation?

Easy
201

A security engineer needs to ensure that if a key is compromised, previous ciphertext can be re-encrypted with a new key version without exposing the plaintext. Which Vault operation should they use?

Hard
202

A Vault operator is troubleshooting a newly deployed Vault server that is initialized but not yet unsealed. The operator needs to understand which component is responsible for holding the unseal keys and root token during the initialization process. Which statement accurately describes the role of the barrier in Vault's architecture?

Medium
203

A developer wants to use Vault to encrypt sensitive data before storing it in a database. They need to perform encryption and decryption operations without ever exposing the encryption key. Which secrets engine should they use?

Easy
204

An organization wants to use Vault's dynamic database credentials to manage MySQL access. They have multiple application servers that need to connect to different databases. What is the best practice for configuring database roles to minimize the number of Vault mounts?

Easy
205

Drag and drop the steps to set up Vault's Kubernetes auth method into the correct order.

Medium
206

An administrator is troubleshooting a policy where a token unexpectedly has permission to read 'secret/data/finance/payroll' even though the attached policy only contains a statement for 'secret/data/hr/*'. The administrator confirms the policy is attached correctly and the path is not covered by any wildcard in it. What is the most likely explanation?

Medium
207

A team wants to store encrypted backups in object storage and needs the ability to rotate the wrapping key over time without re-uploading every backup object. They also want the plaintext data key to be used only in memory by the backup agent. Which combination of Vault transit operations best fits this design?

Hard
208

A security engineer configures the Transit secrets engine at transit/ to encrypt application data. The application must be able to decrypt data but must not be able to create new encryption keys or rotate existing ones. Which policy snippet correctly grants only the required capability for the application's token?

Medium
209

A policy must allow a user to revoke their own token. Which endpoint and capability are required?

Easy
210

An operator needs to create a token role named 'web-app' with a default TTL of 24 hours. Which API request is correct?

Medium
211

Match each Vault term to its definition.

Medium
212

A Vault operator discovers that a service account token was compromised, and that token had created several dynamic database credentials across multiple roles. The operator needs to invalidate every lease created by that token as quickly as possible rather than waiting for each lease to expire. Which action accomplishes this?

Medium
213

A company uses Vault to store application configuration secrets for multiple teams. The Vault cluster is running in production and has the KV secrets engine enabled at the path 'secret/' using version 2. A DevOps engineer, using a Vault token with full admin access, creates a new secret at 'secret/data/team-a/app-config' using the CLI command 'vault kv put secret/team-a/app-config key=value'. The secret is intended for the CI/CD pipeline, which uses a token with a policy that grants 'read' capability on 'secret/data/*'. The pipeline is configured to read the secret by calling the Vault API at the path 'v1/secret/team-a/app-config'. The pipeline reports a 404 Not Found error. The pipeline engineer verifies that the token is valid and has the correct policy attached. All other secrets in the same path can be read successfully by the pipeline. What is the most likely cause of the 404 error?

Hard
214

A Vault admin wants to revoke a specific lease for a dynamic database credential. The admin has the lease ID. Which command should the admin use?

Hard
215

A DevOps team is using Vault tokens with short TTLs for CI/CD jobs. They notice that some jobs fail intermittently with 'permission denied' errors even though the token policy grants the required capabilities. The token is created with a TTL of 10 minutes and renewed automatically by the client library. What is the most likely cause of the failures?

Medium
216

Which THREE of the following are true about using the Vault API with response wrapping? (Choose three.)

Hard
217

A security engineer creates a service token with a TTL of 1 hour and a max TTL of 4 hours. The token is used by an application that renews it every 30 minutes. After 3 hours, the engineer revokes the token using its accessor. What happens to the token's child tokens?

Hard
218

A security engineer needs to create a batch token that will be used by an external system for a one-time operation. The token must be self-contained and not stored in Vault's storage backend. Which token type should be used, and what is a key limitation of that token type?

Medium
219

A developer wants to store an API key for their application in Vault using the key-value secrets engine. They need to be able to retrieve the key and also roll back to a previous version if needed. Which secrets engine configuration should they use?

Easy
220

Drag and drop the steps to initialize and unseal a Vault server for the first time into the correct order.

Medium
221

Which THREE of the following best practices should be followed when using Vault's encryption as a service with the transit engine?

Medium
222

A company wants to use Vault to generate IAM users dynamically for each application, following the principle of least privilege. Which secrets engine configuration should they use?

Medium
223

A CI/CD pipeline runs in a Kubernetes cluster and needs to authenticate to Vault to fetch secrets. The pipeline should not have to manage any long-lived credentials. Which authentication method is most suitable?

Easy
224

A Vault administrator is configuring a new Vault server. The server will store secrets in a HashiCorp Consul cluster. The administrator writes a configuration file with the `storage` stanza pointing to Consul and starts Vault. After initialization and unsealing, the administrator notices that Vault is functioning but wants to ensure that the storage backend is highly available. Which statement about Vault's storage backend is accurate?

Easy
225

Match each Vault replication type to its behavior.

Medium
226

An admin wants to list all enabled authentication methods using the Vault API. Which curl command is correct?

Hard
227

A security team wants to ensure that database credentials generated by Vault are never renewed and have a fixed lifespan of 30 minutes. They configure the role with default_ttl=30m and max_ttl=30m, and set renewable=false. However, they find that some users are able to renew the leases anyway. What could be the reason?

Hard
228

A small development team wants engineers to log in to Vault with a username and password stored directly in Vault, without integrating any external directory or identity provider. Which authentication method should the administrator enable to satisfy this requirement?

Easy
229

Which TWO statements are true about batch tokens?

Easy
230

A security team wants to audit all tokens created by a specific authentication method. They need to list all tokens and retrieve details such as creation time, TTL, and policies. Which Vault command should they use?

Medium
231

A security engineer enables the Transit secrets engine at 'transit/' and creates an encryption key named 'payments' with `vault write -f transit/keys/payments`. The engineer then wants to rotate the key so that new data is encrypted with a new key version while existing ciphertext can still be decrypted. Which command accomplishes this without invalidating existing ciphertext?

Hard
232

An operator runs vault lease list and sees many expired leases. Why are expired leases still listed?

Medium
233

An application needs to obtain short-lived, time-limited credentials to access an external database using username/password authentication. Which secrets engine should be used?

Medium
234

An organization is creating Vault policies to manage access to secrets across multiple application teams. According to HashiCorp best practices, which two approaches should be taken when designing policies? (Choose two.)

Medium
235

An operator needs to create a periodic token with a period of 36 hours. Which command should they use?

Medium
236

A DevOps team wants to authenticate to Vault using short-lived tokens without storing a secret in their CI/CD pipeline. Which authentication method best meets this requirement?

Easy
237

A security architect is designing a Vault deployment where the root key must never exist in plaintext outside of memory and must be split among five key holders. After initialization, the architect wants to ensure that no single administrator can unseal the vault alone. Which Vault architectural feature directly enforces this requirement?

Hard
238

A developer wants to log in to Vault from a terminal by supplying a username and password that Vault stores and manages internally, without relying on any external identity system. Which auth method should be enabled?

Easy
239

A platform team runs Vault with a transit secrets engine mount at transit/. An application requests a new data encryption key with a 30-minute TTL, and the returned lease_id is recorded by the app. Twenty minutes later, the app calls the renew endpoint for that lease. The mount was configured with max_lease_ttl of 1h. What is the maximum TTL the lease can be extended to by this renewal?

Medium
240

Refer to the exhibit. A user with this policy tries to write a new secret to "secret/data/production/db". What will happen?

Easy
241

An administrator wants to allow human users to authenticate using their corporate Active Directory credentials. Which authentication method should they enable?

Easy
242

Which THREE are best practices when selecting authentication methods for different use cases?

Hard
243

A company uses Vault's Kubernetes authentication method to provide secrets to pods. Pods in the 'production' namespace need to read secrets from the path 'secret/data/app/prod'. The administrator has created a Vault role that maps the service account to a policy with capabilities ['read', 'list'] on path 'secret/data/app/*'. However, pods report 'permission denied' when trying to read the secrets. The administrator verifies that the service account has the correct Vault role attached and that the Vault token is being used correctly. What is the most likely cause?

Hard
244

An organization uses Vault's AWS secrets engine to generate temporary IAM credentials. The Vault administrator has set the default lease TTL on the AWS mount to 15 minutes. A developer creates a role with role TTL of 30 minutes and explicit max TTL of 1 hour. Which TWO statements are true regarding the lease behavior for credentials generated under this role?

Hard
245

A developer needs to authenticate to Vault from a CI/CD pipeline running on an on-premises server. The pipeline cannot use cloud provider identities or Kubernetes. The security team wants to avoid embedding long-lived Vault tokens in the pipeline scripts. Which authentication method is most appropriate?

Easy
246

During an audit, it is discovered that a single AppRole role is used by hundreds of applications, and it is impossible to revoke access for a single compromised application without affecting others. What should be done to improve the security posture?

Hard
247

A developer needs to encrypt a short configuration string with the Vault transit secrets engine. The transit engine is mounted at `transit/` and a key named `app-config` has already been created. Which single CLI command correctly sends the plaintext to Vault for encryption?

Easy
248

A platform team wants to provide applications with short-lived AWS credentials that are automatically revoked when their lease expires, without managing long-term IAM users. They also need to allow the applications to assume a role for cross-account access. Which secrets engine should the team enable and configure?

Easy
249

A platform team runs Vault 1.15 with an integrated storage backend. They have enabled the KV v2 secrets engine at the path 'apps/'. A developer deletes the secret at 'apps/data/webapp/db-creds' using `vault kv delete apps/webapp/db-creds`, then immediately reads it back with `vault kv get apps/webapp/db-creds`. What does the developer observe?

Medium
250

A developer created a token and wants to ensure that the token can only be used to read secrets from the 'secret/data/production' path. Which policy attachment approach should be used?

Easy
251

A Vault administrator wants to minimize the impact of a single node failure in a three-node Raft cluster. Which TWO actions will help? (Choose two.)

Hard
252

Which TWO of the following are valid methods to enable a secrets engine at a non-default path in Vault?

Hard
253

A developer needs to generate a new certificate for an internal web service using the PKI secrets engine. A role named 'webserver' has been created. What is the correct command to issue the certificate?

Medium
254

A Vault administrator wants to allow a CI/CD pipeline to create short-lived tokens for deployment jobs. The pipeline itself authenticates with a periodic token. Which token type should the pipeline use to create tokens for jobs, considering the jobs need to be independent and not affected by the pipeline token's lifecycle?

Medium
255

A developer wants to encrypt a password before storing it in a database. The encryption must be deterministic so that the same plaintext always produces the same ciphertext. Which encryption mode should be used in the transit secrets engine?

Medium
256

Which of the following best describes a Vault lease?

Easy
257

A Vault administrator is writing a policy that uses a templated path to allow each user to access their own secrets. The policy is: path "secret/data/users/{{identity.entity.id}}/*" { capabilities = ["read", "list"] } When a user with entity ID "1234" attempts to read 'secret/data/users/1234/profile', they receive a permission denied error. The secret exists, and the user's token has this policy attached. What is the most likely reason for the failure?

Hard
258

A Vault administrator manages a high-availability cluster with Integrated Storage (Raft) and three nodes. The cluster is healthy with one active node and two standby nodes. The administrator needs to perform a planned upgrade of the active node. Before stepping down, the administrator wants to ensure that the standby nodes are ready to take over and that no data loss occurs. Which action should the administrator take to safely transfer leadership?

Hard
259

An operator manages a Vault cluster where several auth methods are enabled at different paths. A developer reports that logging in with the Kubernetes auth method succeeds, but the resulting token has no permissions. The operator confirms the role exists and the service account JWT is valid. Which configuration element is most likely missing?

Medium
260

A CI pipeline authenticates to Vault using the AppRole auth method and needs to obtain a token non-interactively. The pipeline has a role_id and a secret_id but cannot use an interactive login prompt. Which TWO methods can the pipeline use to authenticate and receive a token? (Choose two.)

Medium
261

A security architect is designing a service that uses the Vault transit engine to encrypt records. The architect wants to limit the blast radius if an application token is stolen. The application only ever writes new encrypted records and never needs to read them back. Which transit policy capability set should be granted to the application token?

Medium
262

A company uses Vault to manage secrets for multiple applications. A new security policy requires that all human users authenticate using LDAP and that all machine-to-machine authentication uses AppRole. An administrator has configured an LDAP auth method at 'ldap/' and an AppRole at 'approle/'. The administrator creates a role 'web-app' with a secret ID TTL of 30 days and a token TTL of 1 hour. After deploying the web application, the application successfully logs in using the AppRole role ID and secret ID, retrieves a token, and reads secrets. However, after 1 hour, the application begins receiving 'permission denied' errors when trying to read secrets. The application logs show that it is using the same token obtained during initial login. Which action should the administrator take to resolve this issue?

Easy
263

An administrator wants to mount the AWS secrets engine at 'aws' path using the API. Which request is correct?

Medium
264

Drag and drop the steps to configure Vault's database secrets engine with PostgreSQL into the correct order.

Medium
265

A company uses OIDC auth for human users. After the OIDC provider rotates its signing keys, some users report that they cannot authenticate. The Vault logs show that the OIDC response validation fails. What is the most likely cause?

Medium
266

A developer wants to ensure that their application automatically renews its secret leases before expiration. Which approach is recommended?

Medium
267

A platform team stores application configuration and credentials in a KV v2 secrets engine mounted at 'kv/'. A developer deleted version 3 of the secret 'kv/app/db' by running 'vault kv delete kv/app/db'. Two days later, the security team asks the developer to recover that version because it contained a valid certificate. The developer runs 'vault kv get -version=3 kv/app/db' and receives an error that the version has been deleted. What must the developer do to recover version 3?

Medium
268

A DevOps team is deploying Vault in a Kubernetes cluster. They want to ensure that when a pod starts, it can obtain a short-lived Vault token without human intervention. Which Vault architecture component should they use?

Medium
269

A Vault administrator wants to allow users to authenticate using their corporate Active Directory credentials. Which authentication method should they enable?

Medium
270

A cloud operations team needs Vault to issue short-lived credentials for an external MySQL database. They want Vault to create and revoke users dynamically based on a role. Which secrets engine should they enable and configure?

Easy
271

A company is deploying Vault in a Kubernetes environment. Which three components are essential for a production-ready Vault on Kubernetes? (Choose three.)

Medium
272

A company uses Vault transit to encrypt secrets. They want to periodically rotate the encryption key to comply with compliance requirements. Which TWO actions should be taken? (Choose two.)

Medium
273

An administrator is configuring a new PKI secrets engine at pki/ to issue TLS certificates for internal services. The security team requires that the intermediate CA certificate and its private key are generated inside Vault, and that the root CA remains offline. Which command should the administrator run to create the intermediate CA and generate a CSR for signing by the offline root?

Medium
274

A Vault administrator is reviewing token behaviors and needs to understand which actions are possible with a token's accessor. Which two statements about token accessors are true? (Choose two.)

Medium
275

Match each Vault auth method to its authentication mechanism.

Medium
276

A token with a policy granting 'write' on 'secret/team-alpha/*' is unable to write to 'secret/team-alpha/db-creds' in a KV v2 engine. What is the most likely cause?

Medium
277

An administrator is reviewing Vault token policies and wants to ensure that tokens created by a specific application cannot be renewed and have a fixed lifetime. Which two token configurations should be applied?

Medium
278

A company deploys Vault in a production environment with three nodes using Integrated Storage (Raft). They have configured Performance Replication to a secondary datacenter. The primary datacenter experiences a complete outage. After restoring the primary, they promote the secondary to primary. However, they notice that some secrets written to the primary just before the outage are missing in the secondary. The replication status shows no errors. What is the most likely cause and correct action?

Hard
279

A team is adopting Vault and wants to organize secrets by application and environment (e.g., production, staging). What is the best practice for secrets engine path naming?

Medium
280

A Vault administrator wants to configure a role for dynamic secrets with a default TTL of 1 hour and a max TTL of 4 hours. They also want to allow renewal but only up to the max TTL. Which configuration achieves this?

Medium
281

An administrator wants to create a policy that grants the ability to list all authentication methods enabled on the Vault server. Which path and capability are required?

Medium
282

A team maintains a shared policy that many tokens reference. An administrator needs to add a new path stanza to the policy while preserving every existing rule, without risking a typo that silently removes access. Which approach is correct?

Medium
283

An administrator wants to allow users to authenticate to Vault using their existing corporate GitHub accounts. Which authentication method should be enabled?

Easy
284

A platform team must let a batch job encrypt large files, up to several gigabytes each, using Vault transit. Sending entire files to Vault would exhaust request size limits and add latency. Which approach correctly uses the transit engine while keeping key material inside Vault?

Hard
285

What command is used to view the remaining time on a lease?

Easy
286

A company wants to securely store database credentials for a dynamic application that spins up new instances frequently. They need to ensure each instance gets a unique, time-limited username/password pair with minimal operational overhead. Which approach should they use?

Medium
287

An organization uses the Transit secrets engine to encrypt sensitive files. They want to rotate the encryption key regularly without re-encrypting all existing files. Which feature allows this?

Medium
288

An operator configures a PKI role with allow_any_name=true and max_ttl=72h. A user requests a certificate with common_name='admin.example.com' and ttl=48h. What is the resulting TTL?

Medium
289

What is the purpose of the `storage` stanza in a Vault server configuration file?

Easy
290

A Vault administrator is explaining the role of the storage backend in Vault's architecture. A new team member asks where Vault stores its encrypted data and what the storage backend is responsible for. Which statement accurately describes the storage backend's role?

Easy
291

A user forgets to renew their token before it expires. What happens to the token and its associated leases?

Easy
292

An operations team manages Vault leases for dynamic database credentials. They need to extend the life of an active lease without issuing a new credential, and they also want to confirm the lease's remaining time before doing so. Which two commands or operations should they use? (Choose two.)

Medium
293

A company is running Vault in production with a single active node and two standby nodes using Integrated Storage. The operations team notices that after a network partition, one of the standby nodes becomes unavailable for a few minutes. Upon recovery, the node rejoins the cluster. However, the active node's performance degrades temporarily. What is the most likely cause?

Medium
294

Which THREE steps are required to configure the database secrets engine for generating dynamic credentials?

Hard
295

Which two of the following are valid lease operations? (Choose two.)

Easy
296

An administrator wants to ensure that a token created by a user cannot be used after 24 hours, even if the user tries to renew it. What should the administrator do?

Hard
297

Refer to the exhibit. A Vault administrator configures a three-node cluster with the above configuration on all nodes (with appropriate node_id). After starting all nodes, the administrator unseals node2 and node3. Node1 remains sealed. What will be the cluster state?

Medium
298

An organization needs to store secrets with versioning support, allowing rollback to previous secret values. Which KV secrets engine version should be enabled?

Hard
299

Which TWO are core components of Vault's architecture?

Easy
300

Which TWO of the following are valid methods to authenticate to Vault using the CLI without using a token? (Choose two.)

Easy
301

A Vault cluster uses a Consul storage backend. During a maintenance window, the Consul cluster is taken offline for upgrades. Vault nodes remain running but become unresponsive. After Consul is restored, Vault nodes resume normal operation without manual intervention. Which Vault architectural property explains this behavior?

Medium
302

A security architect is designing a system where one microservice writes encrypted records and a separate reporting microservice reads them. The architect wants the writer to be unable to decrypt anything, while the reader can decrypt but cannot create new ciphertext. Which Vault policy design achieves this with the transit engine?

Hard
303

A security engineer is comparing the AppRole and Kubernetes auth methods for a containerized application. The application runs in a Kubernetes cluster and needs to authenticate to Vault. The engineer wants to minimize the risk of secret leakage and avoid manual secret rotation. Which statement best describes the advantage of Kubernetes auth over AppRole in this scenario?

Hard
304

A cloud operations team needs to provide temporary, dynamically generated credentials for an AWS IAM user to a CI/CD pipeline. The credentials must be automatically revoked when the lease expires. They have configured the AWS secrets engine at 'aws/' with root credentials. Which configuration step is required to allow the pipeline to assume a specific IAM role and receive credentials?

Medium
305

Match each Vault policy capability to its permission.

Medium
306

A payment processing team needs an application to encrypt transaction payloads without ever handling the raw encryption key material. The application will call Vault over mTLS, and the security team insists that the plaintext never leave the application process. Which Vault capability best satisfies this requirement?

Medium
307

Which THREE of the following are true statements about the AppRole authentication method? (Choose three.)

Hard
308

Which THREE are benefits of using Vault response wrapping?

Medium
309

An organization wants to encrypt sensitive fields in their database using Vault. They have multiple applications that need to encrypt different types of data. What approach should they take?

Medium
310

An administrator needs to securely provide a one-time use token to a remote service using Vault response wrapping. Which CLI flag or command should they use?

Hard
311

An organization wants to encrypt data in transit and at rest using a centralized key management system. Which secrets engine is designed for encryption/decryption operations without storing data?

Easy
312

A security analyst discovers that a token used by a legacy application is still active long after the application was decommissioned. Which Vault feature should have been used to automatically expire tokens when the application is no longer running?

Medium
313

An administrator is evaluating Kubernetes auth for workloads running in a cluster. A developer asks whether a pod can authenticate by presenting a service account token directly to Vault without Vault contacting the Kubernetes API. Which statement best describes how the Kubernetes auth method actually validates a login?

Hard
314

Refer to the exhibit. A developer tries to renew a token and receives this error. The token was created using 'vault token create -type=batch'. What is the most likely cause of this error?

Medium
315

An organization needs to automatically issue X.509 certificates for internal services. Which secrets engine should they use?

Easy
316

Which authentication method in Vault uses a shared secret (Role ID) and a dynamic secret (Secret ID) to authenticate machines or applications?

Easy
317

After a security incident, the Vault administrator needs to change the encryption key used to encrypt data at rest. They have already rekeyed the unseal keys. What additional step is required to ensure new secrets are encrypted with a new key?

Hard
318

A security audit requires tracking token usage without exposing the token value itself. Which token attribute should be logged?

Medium
319

A security engineer is building an application that must encrypt records before writing them to an external SaaS ticketing system. The application must never receive or store the encryption key material, and the same plaintext must always produce the same ciphertext so records can be looked up by their encrypted value. Which transit engine configuration should be used?

Medium
320

A platform team enables the transit engine and creates a key named orders. After several months the team rotates the key. A batch job that had stored ciphertext produced before the rotation now needs to read the original data. What must happen for the batch job to recover the plaintext?

Medium
321

Which THREE of the following are correct about using the Vault API to read a secret from KV v2 engine?

Hard
322

A DevOps engineer is configuring Vault to encrypt data in transit for a microservice. They create a key in the transit engine and want to encrypt a base64-encoded plaintext. Which API path and operation should they use?

Medium
323

Drag and drop the steps to enable AppRole authentication in Vault into the correct order.

Medium
324

In a Vault HA cluster, which node is responsible for handling all write requests?

Easy
325

A Vault operator runs 'vault secrets list' and sees 'cubbyhole/' mounted. What is the purpose of this engine?

Easy
326

A DevOps engineer needs to create a token with a specific policy attached using the Vault API. Which API endpoint and request should they use?

Hard
327

Drag and drop the steps to configure Vault's audit logging to a file into the correct order.

Medium
328

Which TWO of the following actions can reduce the number of active leases in Vault? (Select two.)

Easy
329

A startup wants to use Vault to manage MySQL database credentials for their development environment. They have a single MySQL database and require that each application gets unique, short-lived credentials that are automatically rotated. The operations team enabled the database secrets engine, configured the MySQL connection, and created a role with a TTL of 1 hour. However, when an application requests credentials using the role, Vault returns an error: 'No more available leases on this role'. The team checks the role's configuration and sees that the 'max_ttl' is set to 1 hour and 'default_ttl' is also 1 hour. What is the most likely cause of this error?

Easy
330

An administrator creates a token with the following parameters: `vault token create -ttl=1h -explicit-max-ttl=2h`. The token is then renewed once for 1 hour. What is the maximum remaining time the token can be renewed for after this first renewal?

Easy
331

A Vault cluster is sealed. An operator attempts to renew a lease but gets an error. What is the most likely error?

Hard
332

Which THREE are appropriate use cases for Vault's Transit secrets engine?

Medium
333

A user receives 'permission denied' when running 'vault write secret/data/myapp value=123'. The user's token has a policy that includes 'path "secret/data/*" { capabilities = ["read", "list"] }'. What is the most likely cause?

Hard
334

A company uses Vault to issue tokens for short-lived tasks. They have configured a token role with 'period' set to 30 minutes and 'explicit_max_ttl' set to 24 hours. Tokens are created using the role and are expected to be renewed every 30 minutes by the tasks. However, after a few renewals, the Vault audit logs show that a token was renewed but then immediately expired. The task that was using the token failed. What is the most likely reason for this behavior?

Medium
335

Refer to the exhibit. An application uses this policy to access Vault. The application is able to read database credentials from `database/creds/my-role`. However, attempts to list all roles at `database/roles/` fail. What is the most likely cause?

Hard
336

A company requires that Vault data be continuously replicated from a primary data center to a secondary data center for disaster recovery. The secondary data center must be able to become writable in the event of a primary failure. Which Vault feature should they use?

Hard
337

An application uses a periodic token with period=24h. The application renews every 12h. After 48h, the token is still valid. After 72h, the token is still valid. What is the maximum lifetime of this periodic token?

Hard
338

A security engineer needs to authenticate a CI pipeline to Vault using the AppRole auth method from the CLI without a pre-existing token. The engineer has the role_id and a wrapped secret_id. Which TWO commands are required to complete the login and obtain a usable token? (Choose two.)

Medium
339

A security engineer is comparing two machine-oriented auth methods for workloads running outside Kubernetes. The workloads cannot use cloud instance identity and must not store a long-lived credential on disk. The engineer wants a method where the workload proves possession of a one-time-use credential that can be issued with a very short TTL and limited use count. Which auth method best fits?

Hard
340

A developer has a policy that grants 'create' capability on path 'secret/data/team/*'. They successfully create a new secret using 'vault kv put secret/data/team/db', but when they try to update the same secret with new data, they get a permission denied error. What is the most likely cause?

Medium
341

After rotating the 'payment-key', Vault successfully decrypts data encrypted with the old key (v1). What is the most likely reason the decryption succeeded?

Hard
342

A Vault policy includes the following statement: path "secret/data/+/app" { capabilities = ["read"] }. Which paths would match this policy? (Assume KV v2)

Hard
343

An organization uses the AWS secrets engine to generate IAM users for each application. They want to ensure that if a Vault server is compromised, the attacker cannot use the AWS secrets engine configuration to gain access to the AWS account. Which additional security measure should be implemented?

Hard
344

A Vault cluster has several policies. One policy, "app-policy", contains: path "secret/data/app/*" { capabilities = ["create", "update"] }. Another policy, "admin-policy", includes: path "secret/data/app/db" { capabilities = ["deny"] }. A token is attached with both policies. Can the token write to "secret/data/app/db"?

Hard
345

A financial services company uses Vault's PKI secrets engine to issue short-lived TLS certificates to internal services. An administrator configured the PKI role with default_ttl=24h and max_ttl=72h. A service requests a certificate with an explicit TTL of 120h. What will Vault do in this situation?

Hard
346

A platform team runs a Vault cluster with a transit secrets engine mount at transit/. An application holds a token with a policy granting only "update" on transit/encrypt/orders and "read" on transit/keys/orders. The application's token has a TTL of 1h with a max_ttl of 4h, and it renews itself every 30 minutes using the token renewal endpoint. After roughly four hours of continuous operation, the application's API calls begin failing with a permission denied error even though the token was renewed successfully each time. Which Vault behavior explains this failure?

Medium
347

Which TWO of the following are valid use cases for the Transit secrets engine? (Select exactly 2.)

Medium
348

A Vault cluster uses Consul for HA. After a brief network partition, a standby node loses contact with the active node. What does the standby node do after a timeout?

Easy
349

A Vault cluster uses performance replication. A performance standby node is not responding to read requests. What is the most likely cause?

Medium
350

Refer to the exhibit. What seal mechanism is configured for this Vault instance?

Medium
351

Refer to the exhibit. What is the purpose of the -field=ciphertext flag in this command?

Medium
352

A security engineer wants to ensure that all requests to Vault are logged for compliance. Which component must be configured?

Easy
353

Which THREE are required for Vault to encrypt data at rest? (Choose three.)

Medium
354

An administrator wants to write a secret 'myapp' with value 'password=pass123' to the KV v2 secret engine mounted at 'secret/'. Which command should they use?

Easy
355

A team has set up automatic key rotation on a transit key. After rotation, encrypted data that was encrypted with the previous key version can no longer be decrypted. What is the most likely cause?

Hard
356

Which TWO of the following are features of the AWS secrets engine compared to the Azure secrets engine?

Easy
357

An organization uses Kubernetes pods to access Vault. They want to avoid hardcoding any secrets in the pod definition. Which authentication method should they use?

Medium
358

A DevOps team is setting up a Vault cluster for the first time. They plan to use AWS KMS for auto-unseal and Consul as the storage backend. As part of the architecture, which TWO components are essential for the Vault server to start and serve requests?

Easy
359

Refer to the exhibit. A user wants to write a secret 'db_password' with value 's3cret' to this secrets engine. Which CLI command should be used?

Easy
360

A security team is evaluating the Vault transit secrets engine as an encryption-as-a-service platform for several applications. They want to understand which capabilities the transit engine actually provides. (Choose two.)

Medium
361

An organization wants to encrypt data at rest in a cloud storage bucket. They plan to use Vault's transit engine to generate a data key and then encrypt the data locally. Which transit endpoint should they use to get a data key?

Easy
362

A Vault cluster has a token with the following policy: path "secret/data/dev/*" { capabilities = ["read", "list"] }. The token is used to read a secret at "secret/data/dev/password". The read succeeds. Later, the token tries to read "secret/data/prod/password". What happens?

Hard
363

A security engineer is enabling the Transit secrets engine at the path 'transit/'. They need to encrypt data without ever exposing the plaintext key material to the application, and they want the ciphertext to be safely stored in an external database. They also require the ability to rotate the encryption key periodically without re-encrypting existing data. Which command correctly configures a new encryption key named 'orders' for this purpose?

Medium
364

Which THREE are valid operations in the Vault transit secrets engine? (Choose three.)

Medium
365

A security administrator wants to create a policy that allows a service to renew its own token and list its own token capabilities, but not create new tokens. Which policy statements should be included?

Medium
366

Drag and drop the steps to perform a Vault disaster recovery using the replication feature into the correct order.

Medium

Frequently asked questions

What does the troubleshooting domain cover on the VA-003 exam?
troubleshooting questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 366 troubleshooting questions in the VA-003 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only troubleshooting questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.